Disclosure of Private Message Excerpts in Discourse Discussion Platform
CVE-2026-59829

4.3MEDIUM

Key Information:

Vendor

Discourse

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-59829?

On the Discourse discussion platform, a vulnerability was identified where category group moderators could access excerpts of private messages in flag notifications, despite not being part of those discussions. This issue arises when category group moderation is enabled, allowing unauthorized visibility into flagged content. The flaw affects several versions of Discourse but has been resolved in updates 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, ensuring that such sensitive information remains confidential.

Affected Version(s)

discourse >= 2026.1.0-latest, < 2026.1.6 < 2026.1.0-latest, 2026.1.6

discourse >= 2026.5.0-latest, < 2026.5.2 < 2026.5.0-latest, 2026.5.2

discourse < 2026.6.1 < 2026.6.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.